Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-31819
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each…
Halibut
4.4.7+
CRITICAL 9.8
CVE-2021-39392
The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the …
Mylittlebackup
after 1.7
CRITICAL 10.0
CVE-2021-37181
A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus…
Cerberus Dms
Patch available
HIGH 8.8
CVE-2021-39207
parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is v…
Parlai
1.1.0+
CRITICAL 9.8
CVE-2021-24040EPSS 17%
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input,…
Parlai
1.1.0+
CRITICAL 9.8
CVE-2021-37579EPSS 7%
The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…
Dubbo
2.7.13 / 3.0.2+
HIGH 8.1
CVE-2021-32836
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserializat…
Zstack
3.10.12 / 4.1.6+
HIGH 8.8
CVE-2021-35217EPSS 73%
Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and r…
Patch Manager
after 2020.2.5
CRITICAL 9.8
CVE-2021-36163
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…
Dubbo
after 3.0.1
HIGH 7.8
CVE-2021-32568
mrdoc is vulnerable to Deserialization of Untrusted Data
Mrdoc
after 0.7.0
HIGH 8.8
CVE-2021-35215EPSS 70%
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit …
Orion Platform
after 2020.2.5
HIGH 8.8
CVE-2021-35216EPSS 81%
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An …
Patch Manager
2020.2.6+
HIGH 8.8
CVE-2021-35218EPSS 76%
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network acces…
Orion Platform
2020.2.6+
HIGH 8.8
CVE-2021-36231
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating syste…
Mik.starlight
No fix yet
HIGH 8.8
CVE-2021-21677
Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from dis…
Code Coverage Api
after 1.4.0
HIGH 8.8
CVE-2021-36981EPSS 6%
In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.
Verinice
1.22.2+
HIGH 8.8
CVE-2021-39132
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an autho…
Rundeck
3.3.14 / 3.4.3+
CRITICAL 9.8
CVE-2021-34066
An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow attackers to exe…
Developer Be
1.0+
CRITICAL 9.8
CVE-2021-21741
There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit…
Zxv10 M910 Firmware
Mitigation only
HIGH 8.8
CVE-2021-24579EPSS 8%
The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unserialize() function without any v…
Bold Page Builder
3.1.6+
HIGH 7.8
CVE-2021-21869
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development …
Codesys
Patch available
HIGH 7.5
CVE-2021-31010 KEV
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and…
Ipados
7.6.2 / 10.15.7+
HIGH 8.5
CVE-2021-39152EPSS 11%
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…
Fedora
1.4.18+
HIGH 8.5
CVE-2021-39150
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…
Fedora
1.4.18+
MEDIUM 6.3
CVE-2021-39140EPSS 6%
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to alloca…
Debian Linux
1.4.18+
HIGH 8.5
CVE-2021-39153
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…
Fedora
1.4.18+
HIGH 8.5
CVE-2021-39154
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…
Fedora
1.4.18+
HIGH 8.5
CVE-2021-39141EPSS 16%
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…
Debian Linux
1.4.18+
HIGH 8.5
CVE-2021-39144 KEVEPSS 98%
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…
Debian Linux
1.4.18+
HIGH 8.5
CVE-2021-39145
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…
Debian Linux
1.4.18+